Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)10%—Nodejs Node.jsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+428/11/201817/6/2026
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from…
ModificadaMedia (5.5)0.39%—Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+326/11/201817/6/2026
The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service.
ModificadaMedia (6.5)2.1%—Exiv2Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+226/11/201817/6/2026
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
ModificadaAlta (7.8)9.5%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
ModificadaCrítica (9.8)7.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+421/11/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
ModificadaMedia (4.7)3.4%💥 ExploitCanonical Ubuntu LinuxDebian LinuxNodejs Node.jsOpenssl+1615/11/201817/6/2026
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
ModificadaAlta (8.8)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
ModificadaMedia (4.7)1.4%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
ModificadaMedia (6.1)0.88%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .
ModificadaMedia (6.5)1.7%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.2%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaMedia (6.5)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (6.1)1.2%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
ModificadaAlta (8.8)1.5%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
ModificadaAlta (8.8)1.8%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.5%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
ModificadaMedia (6.1)0.85%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
ModificadaMedia (6.5)1.6%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
ModificadaMedia (4.3)0.97%—Google ChromeRedhat Linux DesktopRedhat Linux ServerRedhat Linux Workstation+114/11/201817/6/2026
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/11/201817/6/2026
Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.